
Information Systems Security Management Professional
Domain 1Objective 7
1.7 Define, Measure, and Report Security Metrics ISSMP Practice Questions (Page 2)
Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
21%of the exam
Questions 6–10
- 6
What does it mean to 'map a metric to the organization's risk posture'?
Select an answer first - 7
An organization with a low risk appetite is selecting security metrics. Which metric is most appropriate?
Select an answer first - 8
Which statement best defines a Key Performance Indicator (KPI) in the context of security management?
Select an answer first - 9
A security team tracks the KPI 'percentage of security patches applied within 30 days of release'. The metric has been stable at 95% for the past year. However, the number of incidents exploiting known vulnerabilities has increased by 40% in the last quarter. What is the most likely explanation for this discrepancy, and what should the team do?
Select an answer first - 10
A CISO is building a metrics dashboard for two different audiences: the board of directors and the security operations team. The board needs to understand the overall effectiveness of the security program. The SOC team needs to understand the effectiveness of their detection and response processes. Which pair of metrics best serves these two distinct audiences?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.